I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
Backdoor Bifrose
Also known as: Trojan Agent, Trojan Graftor
SHA256: 9e532753eec6c1eadebbd2ab4aedd121d757746a0224880964828ae0a8e65c48
SHA1: f64e3848cf948c7612b6a2cd35bcbbd5ce7e3af5
MD5: 0eadd75636e7e351748fe506d4b96e23
File size: 904192 bytes
Created files:
C:\windows\system32\dmprrv.dll – Backdoor Bifrose
C:\windows\system32\kernel31.dll – Backdoor Bifrose
%Temp%\IXP000.TMP\mspaint.exe – Backdoor Bifrose
%Temp%\IXP000.TMP\mstsc.exe – Backdoor Bifrose
%Temp%\IXP000.TMP\netsetup.exe – Backdoor Bifrose
%Temp%\IXP000.TMP\sndrec32.exe – Backdoor Bifrose
%Temp%\IXP000.TMP\sndvol32.exe – Backdoor Bifrose
%Temp%\IXP000.TMP\tun.exe – Backdoor Bifrose
%Temp%\IXP000.TMP\twff.exe – Backdoor Bifrose
Backdoor Bifrose created autostart registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%Temp%\IXP000.TMP\”
HKLM\System\CurrentControlSet\Services\dmprrv\Type: 10010000
HKLM\System\CurrentControlSet\Services\dmprrv\Start: 02000000
HKLM\System\CurrentControlSet\Services\dmprrv\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\dmprrv\DisplayName: dmprrv
HKLM\System\CurrentControlSet\Services\dmprrv\ImagePath: %WinDir%\System32\svchost.exe -k dmprrv
HKLM\System\CurrentControlSet\Services\dmprrv\Parameters\ServiceDll: 2500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C0064006D0070007200720076002E0064006C006C000000